CyberRota Analysis
AI-GeneratedThe TTSSH2 plugin of Tera Term is vulnerable due to improper handling of length parameter inconsistencies, which can lead to out-of-bounds read/write operations during SSH connections to malicious servers. This vulnerability may allow attackers to access adjacent memory contents, potentially leading to unexpected behavior or crashes of the Tera Term application. Organizations using Tera Term for SSH connections should prioritize addressing this vulnerability to mitigate risks associated with unauthorized data exposure and application instability.
Original NVD Description
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.